AI Agent Finds 21 FFmpeg Zero-Days for $1,000

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- depthfirst deployed an autonomous security agent against FFmpeg's roughly 1.5 million lines of C, producing 21 confirmed zero-days with reproducible PoC inputs at a cost of around $1,000.
- Several FFmpeg bugs had been latent for 15 to 20 years; one stack overflow in the service-description-table code dates to 2003, sitting undiscovered for 23 years.
- Chrome 149 patches 429 vulnerabilities, a single-release record, with over 100 rated critical or high severity; the worst, CVE-2026-10881 (CVSS 9.6), is an ANGLE graphics engine out-of-bounds read/write that earned a $97,000 bounty.
- Of Chrome 149's ~90 high-severity bugs, only 10 came from outside researchers, and 19 of 22 critical bugs were Google's own finds — the AI connection there is volume, not authorship.
- Google overhauled its bug bounty in April after a flood of AI-generated submissions, now requesting concise reproducers over the long writeups AI tends to produce.
- Anthropic's Mythos model pulled a 16-year-old H.264 flaw and others out of FFmpeg for about $10,000, with three of those shipping in FFmpeg 8.1.
Why it matters: Finding vulnerabilities has become cheap and automated — depthfirst's roughly $1,000 run produced 21 zero-days, several over two decades old — but triage, patching, and getting fixes to end users still rests on a thin human layer that cannot scale at the same pace, leaving downstream packagers (Python wheels, container images, embedded appliance copies) exposed during the gap.

